VYPR

DHL Shipping Germany for WooCommerce

by WordPress

CVEs (2)

  • CVE-2026-16981MedAug 5, 2026
    risk 0.34cvss 5.3epss 0.00

    The DHL Shipping Germany for WooCommerce WordPress plugin before 4.0.1 does not perform any authorization check (no capability, nonce, login, or ownership check) on one of its shipping-label download endpoints, so an unauthenticated attacker can enumerate sequential ids and…

  • CVE-2026-16993LowAug 5, 2026
    risk 0.24cvss 3.7epss 0.00

    The DHL Shipping Germany for WooCommerce WordPress plugin before 4.0.1 does not protect its shipping-label storage directory with server-independent access control, relying only on an Apache .htaccess file, so on a web server that does not honor .htaccess (such as nginx) an…